Описание
Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | not-affected | 2.3.14.1 |
hardy | ignored | end of life |
karmic | ignored | end of life |
lucid | released | 2.2.3-2ubuntu0.1 |
maverick | released | 2.3.5-1.1ubuntu0.1 |
natty | released | 2.3.5-1.2ubuntu1.1 |
upstream | released | 2.3.11,3.0.4 |
Показывать по
6.8 Medium
CVSS2
Связанные уязвимости
Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.
Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3. ...
6.8 Medium
CVSS2